openPR Logo
Press release

The new PCI DSS version 2 is effective. What now?

01-21-2011 09:26 PM CET | IT, New Media & Software

Press release from: QueryClick Ltd

The PCI Security Standards Council (PCI SSC) is a global, open industry standards body providing management of the Payment Card Industry Data Security Standard (PCI DSS), PIN Transaction Security (PTS) requirements and the Payment Application Data Security Standard (PA-DSS). The PCI SCC has released the new version 2 of its PCI Data Security Standard (PCI DSS) which has become effective on 1st January 2011.

The new standard begins the three year lifecycle that allows for validation against the previous version of the standard (1.2.1) until 31st December 2011. This provides stakeholders time to understand and implement the new version of the standard as well as provide feedback. The PCI SCC encourages organizations to transition to the updated version as soon as possible.

The changes in version 2.0 introduce no new major requirements. The majority of changes are modifications to the language to clarify the meaning of the requirements and make understanding and adoption easier. Many of the revisions reinforce the need for a thorough scoping exercise prior to assessment in order to:
 understand where cardholder data resides;
 reduce the infrastructure and applications subject to the standard;
 allow organizations to adopt a risk-based approach when assessing;
 prioritizing vulnerabilities based on specific business circumstances;

Principal Assurance Consultant André Coner of Information Security consultants commissum.com [http://www.commissum.com/en/] commented that many organisations fail to adequately segment the cardholder data environment from the remainder of it’s network and therefore are significantly increasing the complexity and cost of their PCI DSS compliance. Without adequate network segmentation, the entire network is in scope of the PCI DSS assessment. Segmentation is therefore strongly recommended as it will reduce the scope and cost of the PCI DSS assessment. It also reduces the cost and difficulty of implementing and maintaining the PCI DSS controls.

The commissum information security managed services provides services for PCI DSS Requirement 11: “Regular test security systems and processes”. This includes:

 Quarterly security scanning.
 Penetration testing: network and application.
 Host configuration reviews of firewalls and network infrastructure.
 Web Application Security Assessment (WASA).
 Wireless Security Assessments.
 Securing the software development lifecycle.
 Code review.
 Recommendation of compensating controls.

About commissum:
With 20 years of experience, commissum is adept at offering practical advice and recommending cost-effective solutions, to deliver a joined-up, coherent approach to protecting an organisation's information assets.

Quay House,
142 Commercial Street,
Leith, Edinburgh,
EH6 6LB,
Scotland,
United Kingdom
t: 0845 644 3217
f: 0845 644 3218

This release was published on openPR.

Permanent link to this press release:

Copy
Please set a link in the press area of your homepage to this press release on openPR. openPR disclaims liability for any content contained in this release.

You can edit or delete your press release The new PCI DSS version 2 is effective. What now? here

News-ID: 159493 • Views:

More Releases from QueryClick Ltd

Sports nutrition experts USN re-launch website featuring highlights such as the new USN Life
09-17-2013 | Sports
QueryClick Ltd
Sports nutrition experts USN re-launch website featuring highlights such as the …
USN Life is a new online resource offered by sports nutrition experts USN and featuring health and fitness information, articles and training plans As part of a recent website update, sports supplement providers USN have created a new resource for anyone concerned with boosting their fitness and wellness levels. USN Life is aimed at the full breadth of USN's customers, from professional athletes and bodybuilders to amateur sportspeople or those simply
Sports supplement provider USN launches revamped website and updated product ranges
09-17-2013 | Sports
QueryClick Ltd
Sports supplement provider USN launches revamped website and updated product ran …
Popular nutritional supplement provider USN re-launches website with a host of updated products and extra resources for athletes and bodybuilders. USN, a leading supplier of sports nutrition and bodybuilding supplements, has announced the launch of an updated website. Fast becoming a household name, the company has revamped its site with the aim of offering even more information and advice to anyone who is looking to lose weight, gain muscle

More Releases for PCI

Analog control via PCI/PCI Express with electrical isolation
Maisach/Munich/Germany. With the analog output modules MDA16-2i/-4i/-8i, the manufacturer of measurement technology BMC Messsysteme GmbH (bmcm) launches a module series for isolated, analog control via the PCI or PCI Express bus. If for the control of power supplies, frequency converters, or engines - potential differences between two circuits can lead to sudden discharges and cause heavy damages. Galvanic isolation is the solution here. With the new plug-on modules MDA16-2i, MDA16-4i, and MDA16-8i
BeroNet Launches Berofix With PCI-Express
Berlin, January 8, 2010 – beroNet GmbH, a leader in Voice-over-IP (VoIP) technologies that accelerate the deployment and enable the management of next generation Line-Interface-Cards, announced its newest berofix PCI-Express cards. With berofix PCI-Express card, the latest addition to the card series of berofix, the VoIP experts from Germany demonstrate their practical experience again. PCI Express (Peripheral Component Interconnect Express), officially abbreviated as PCIe (or PCIe, as it is commonly called),
eRevMax receives PCI compliance certification
London/ Kolkata, December 10, 2009 – eRevMax has received Payment Card Industry Data Security Standard (PCI DSS) certification from the PCI Security Standards Council, proving the presence of secure and robust systems within the eRevMax portfolio. The company has ensured its products are compliant with international security best practices and principles which further prove its standing in the industry as a provider of premium quality and secure services. eRevMax has implemented
Measuring via PCI-Express
Maisach/Munich/Germany. With the PCIe-BASE, BMC Messsysteme GmbH (bmcm) is one of the first few manufacturers of measurement technology to come out with a competitive data acquisition card for the PCI Express interface. PCI Express (Peripheral Component Interconnect Express), "PCIe" for short, is a PC interface allowing for the communication of peripheral components with the master processor of the PC. In the long term, PCIe will replace the PCI slots in
Fanless Intel Atom Embedded Computer Offers Wide Power Input Range, Extended Ope …
(Taipei, Taiwan - May 12, 2009) Lanner Electronics, Inc., a leading designer and ODM manufacturer of advanced embedded computing platforms for commercial and industrial applications, today announced the release of the Lanner LUGE LEC-2010 – a small form factor, fanless embedded system based on the Intel® Atom™ processor designed for a broad range of industrial and mobile computing applications. The LEC-2010 expands on Lanner’s growing line of Atom-based small form
Kontron KISS PCI 759: Multi-core industrial servers for PICMG 1.0 based PCI/ISA …
Eching, Germany, May 29, 2008 – Today, Kontron announced its latest range of 2U and 4U KISS industrial servers that bring Intel® Core™2 Duo processor performance to PICMG 1.0 based PCI/ISA applications. These long term available, ultra quiet ( < 35 dB) industrial servers are especially designed for applications that require high data processing performance without the need for high-speed PCI Express features. Designed around the Intel® 945G chipset with